Malicious PDF — malware analysis report

Static analysis result for SHA-256 52e773df733812f5…

MALICIOUS

PDF

19.3 KB Created: 2019-05-02 17:41:43 +01:00 Authoring application: mPDF 5.7
MD5: 3268173c1a5662faf5d655bcafe750be SHA-1: 6d44ed2483e1780dfb2a3950cc43e48ca589ecf8 SHA-256: 52e773df733812f5a09bd094cc7d46199100e14e359b195b0e922598a01ef02d
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links to external PDF files, all hosted on the same domain. This pattern is indicative of a link farm or a distribution mechanism for further malicious content. The ML classifier strongly supports the malicious verdict. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9920

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/2093095090091/Music-Like-Dirt-A-Chapbook-by-Frank-Bidart.pdf
    • http://loaminoo.linkpc.net/1098096092090095/Red-Dirt-Heart-4-Red-Dirt-4-by-N-R-Walker.pdf
    • http://loaminoo.linkpc.net/1099092096091091/Red-Dirt-Heart-Imago-Red-Dirt-4-5-Imago-2-5-by-N-R-Walker.pdf
    • http://loaminoo.linkpc.net/1096092097/Hollywood-Dirt-Hollywood-Dirt-1-by-Alessandra-Torre.pdf
    • http://loaminoo.linkpc.net/9093095099096099/Reflections-on-American-Music-The-Twentieth-Century-and-the-New-Millennium-A-Collection-of-Essays-Presented-in-Honor-of-the-College-Music-Society-Cms-Bibliographies-in-American-Music-No-16-by-Michael-Benton-Saffle.pdf
    • http://loaminoo.linkpc.net/9090097098091096/More-Easy-Classics-to-Moderns-Music-for-Millions-Vol-27-Music-for-Milions-Music-for-Milions-by-A-Traum.pdf
    • http://loaminoo.linkpc.net/3095096093090090/Breath-by-Tim-Winton.pdf
    • http://loaminoo.linkpc.net/1099091098090090/Minimum-of-Two-by-Tim-Winton.pdf
    • http://loaminoo.linkpc.net/5093091099096/Cloudstreet-by-Tim-Winton.pdf
    • http://loaminoo.linkpc.net/2099097090093098/Beyond-Nostalgia-by-Tom-Winton.pdf
    • http://loaminoo.linkpc.net/1090092092092096/The-Turning-by-Tim-Winton.pdf
    • http://loaminoo.linkpc.net/6094091094091/Blueback-by-Tim-Winton.pdf
    • http://loaminoo.linkpc.net/6093093092095/Cloudstreet-by-Tim-Winton.pdf
    • http://loaminoo.linkpc.net/3095090094095098/The-Riders-by-Tim-Winton.pdf
    • http://loaminoo.linkpc.net/6098091099098091/Reel-Music-Exploring-100-Years-of-Film-Music-by-Roger-Hickman.pdf
    • http://loaminoo.linkpc.net/4094094091090091/Soul-of-Music-and-Other-Music-Stories-from-South-India-by-Anant-Acharya.pdf
    • http://loaminoo.linkpc.net/2098092098098090/The-Music-Parents-Guide-A-Survival-Kit-for-the-New-Music-Parent-by-Anthony-Mazzocchi.pdf
    • http://loaminoo.linkpc.net/4094091099092092/Music-Express-The-Rise-Fall-Resurrection-of-Canada-s-Music-Magazine-by-Keith-Sharp.pdf
    • http://loaminoo.linkpc.net/8096096090090097/Music-s-Great-Enigma-Unraveling-the-mystery-behind-modern-music-nomenclature-Could-there-be-a-better-way-by-James-Othon.pdf
    • http://loaminoo.linkpc.net/6093093096091094/Music-and-Language-The-Rise-of-Western-Music-as-Exemplified-in-Settings-of-the-Mass-by-Thrasybulos-Georgos-Georgiades.pdf
    • http://loaminoo.linkpc.net/3095096